CVE-2017-9526

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
11/06/2017
Last modified:
20/04/2025

Description

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnupg:libgcrypt:*:*:*:*:*:*:*:* 1.7.6 (including)